Known vulnerabilities in wordpress (Debian package) 5.0.10+dfsg1-0+deb10u1

Vendor: Debian
Version: 5.0.10+dfsg1-0+deb10u1
Software CPE: cpe:2.3:o:debian:wordpress_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 15
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting wordpress (Debian package) version 5.0.10+dfsg1-0+deb10u1 wordpress (Debian package) 5.0.10+dfsg1-0+deb10u1 is affected by 15 vulnerabilities: 5 high, 7 medium, 3 low Critical High Medium Low

Vulnerabilities (15)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU59291 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-21664
CWE-89 High
No
No
5.0.15+dfsg1-0+deb10u1, 5.7.5+dfsg1-0+deb11u1 07.01.2022 SB2022010706
SB2022011113
SB2022010719
and 2 more
#VU59290 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-21661
CWE-89 High
Public exploit available
No
5.0.15+dfsg1-0+deb10u1, 5.7.5+dfsg1-0+deb11u1 07.01.2022 SB2022010706
SB2022011113
SB2022010719
and 2 more
#VU59289 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-21663
CWE-94 Low
No
No
5.0.15+dfsg1-0+deb10u1, 5.7.5+dfsg1-0+deb11u1 07.01.2022 SB2022010706
SB2022011113
SB2022010719
and 2 more
#VU59288 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-21662
CWE-79 Medium
No
No
5.0.15+dfsg1-0+deb10u1, 5.7.5+dfsg1-0+deb11u1 07.01.2022 SB2022010706
SB2022011113
SB2022010719
and 2 more
#VU56462 - Exposure of sensitive information to an unauthorized actor
CVE-2021-39200
CWE-200 Medium
No
No
5.0.14+dfsg1-0+deb10u1, 5.7.3+dfsg1-0+deb11u1 13.09.2021 SB2021091307
SB2021101502
#VU56461 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-39201
CWE-79 Low
No
No
5.0.14+dfsg1-0+deb10u1, 5.7.3+dfsg1-0+deb11u1 13.09.2021 SB2021091306
SB2021101502
#VU48200 - Deserialization of Untrusted Data
CVE-2020-28032
CWE-502 High
Public exploit available
No
5.0.11+dfsg1-0+deb10u1 02.11.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48201 - Permissions, Privileges, and Access Controls
CVE-2020-28033
CWE-264 Medium
No
No
5.0.11+dfsg1-0+deb10u1 02.11.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48202 - Improper Access Control
CVE-2020-28036
CWE-284 High
No
No
5.0.11+dfsg1-0+deb10u1 02.11.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48040 - Cross-Site Request Forgery (CSRF)
CVE-2020-28040
CWE-352 Medium
No
No
5.0.11+dfsg1-0+deb10u1 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48039 - Improper Access Control
CVE-2020-28039
CWE-284 Medium
No
No
5.0.11+dfsg1-0+deb10u1 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48038 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-28038
CWE-79 Low
Public exploit available
No
5.0.11+dfsg1-0+deb10u1 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48037 - Resource Management Errors
CVE-2020-28037
CWE-399 High
No
No
5.0.11+dfsg1-0+deb10u1 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48036 - Permissions, Privileges, and Access Controls
CVE-2020-28035
CWE-264 Medium
No
No
5.0.11+dfsg1-0+deb10u1 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more
#VU48035 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-28034
CWE-79 Medium
No
No
5.0.11+dfsg1-0+deb10u1 30.10.2020 SB2020103007
SB2020110901
SB2020110930
and 5 more